ASN Lookup API: The Complete Network Profile

The ASN Lookup API returns the complete network profile behind any AS number or IP address: the owning organization, its type, website, and country of registration, announced IPv4 and IPv6 route prefixes, peers, upstreams, downstreams, and the raw WHOIS record. One call answers who runs a network, what they announce, and who they connect to. Free trial available.

    • stringip:"216.73.217.15",
    • objectasn:Object,
      • stringas_number:"AS16509",
      • stringorganization:"Amazon.com, Inc.",
      • stringcountry:"US",
      • stringtype:"HOSTING",
      • stringdomain:"amazon.com",
      • stringdate_allocated:"2000-05-04",
      • stringasn_name:"AMAZON-02",
      • stringallocation_status:"",
      • stringnum_of_ipv4_routes:"15692",
      • stringnum_of_ipv6_routes:"5749",
      • stringrir:"ARIN",
      • routes:Array[21441],
        • stringroutes[0]:"52.46.9.0/24",
        • stringroutes[1]:"173.195.230.0/24",
        • stringroutes[2]:"2600:9000:22c3::/48",
        • stringroutes[3]:"3.172.81.0/24",
        • stringroutes[4]:"2600:9000:2467::/48",
        • stringroutes[5]:"2600:f0f0:8170::/48",
        • stringroutes[6]:"3.172.35.0/24",
        • stringroutes[7]:"13.32.240.0/24",
        • stringroutes[8]:"2a05:d035:4080::/46",
        • stringroutes[9]:"64.226.232.0/21",
        • ... and 21431 more
      • downstreams:Array[117],
        • objectdownstreams[0]:Object,
          • stringas_number:"AS54920",
          • stringdescription:"Phaedon Acquisition, Inc.",
          • stringcountry:"US",
        • objectdownstreams[1]:Object,
          • stringas_number:"AS139216",
          • stringdescription:"Htroy Network Research Limited",
          • stringcountry:"CN",
        • objectdownstreams[2]:Object,
          • stringas_number:"AS214160",
          • stringdescription:"Shreejal Maharjan",
          • stringcountry:"GB",
        • objectdownstreams[3]:Object,
          • stringas_number:"AS213151",
          • stringdescription:"Christian Elsen",
          • stringcountry:"DE",
        • objectdownstreams[4]:Object,
          • stringas_number:"AS401106",
          • stringdescription:"Techies365",
          • stringcountry:"US",
        • objectdownstreams[5]:Object,
          • stringas_number:"AS153661",
          • stringdescription:"EVERLIGHT RADIOLOGY LIMITED",
          • stringcountry:"AU",
        • objectdownstreams[6]:Object,
          • stringas_number:"AS36262",
          • stringdescription:"HashTable, Inc.",
          • stringcountry:"US",
        • objectdownstreams[7]:Object,
          • stringas_number:"AS401041",
          • stringdescription:"Axis Security",
          • stringcountry:"US",
        • objectdownstreams[8]:Object,
          • stringas_number:"AS401181",
          • stringdescription:"Cordial",
          • stringcountry:"US",
        • objectdownstreams[9]:Object,
          • stringas_number:"AS61162",
          • stringdescription:"Klarna Bank AB",
          • stringcountry:"SE",
        • ... and 107 more
      • upstreams:Array[189],
        • objectupstreams[0]:Object,
          • stringas_number:"AS12552",
          • stringdescription:"GlobalConnect AB",
          • stringcountry:"SE",
        • objectupstreams[1]:Object,
          • stringas_number:"AS5511",
          • stringdescription:"Orange S.A.",
          • stringcountry:"FR",
        • objectupstreams[2]:Object,
          • stringas_number:"AS6762",
          • stringdescription:"TELECOM ITALIA SPARKLE S.p.A.",
          • stringcountry:"IT",
        • objectupstreams[3]:Object,
          • stringas_number:"AS39249",
          • stringdescription:"Netassist International EOOD",
          • stringcountry:"BG",
        • objectupstreams[4]:Object,
          • stringas_number:"AS29695",
          • stringdescription:"Lyse Tele AS",
          • stringcountry:"NO",
        • objectupstreams[5]:Object,
          • stringas_number:"AS37273",
          • stringdescription:"Bandwidth and Cloud Services Group Ltd",
          • stringcountry:"UG",
        • objectupstreams[6]:Object,
          • stringas_number:"AS286",
          • stringdescription:"GTT Communications Inc.",
          • stringcountry:"US",
        • objectupstreams[7]:Object,
          • stringas_number:"AS15943",
          • stringdescription:"wilhelm.tel GmbH",
          • stringcountry:"DE",
        • objectupstreams[8]:Object,
          • stringas_number:"AS4230",
          • stringdescription:"CLARO S.A.",
          • stringcountry:"BR",
        • objectupstreams[9]:Object,
          • stringas_number:"AS31500",
          • stringdescription:"Global Network Management Inc",
          • stringcountry:"AG",
        • ... and 179 more
      • peers:Array[859],
        • objectpeers[0]:Object,
          • stringas_number:"AS28792",
          • stringdescription:"Public Internet Ltd",
          • stringcountry:"GB",
        • objectpeers[1]:Object,
          • stringas_number:"AS40994",
          • stringdescription:"Hohl IT e.U.",
          • stringcountry:"AT",
        • objectpeers[2]:Object,
          • stringas_number:"AS37273",
          • stringdescription:"Bandwidth and Cloud Services Group Ltd",
          • stringcountry:"UG",
        • objectpeers[3]:Object,
          • stringas_number:"AS38880",
          • stringdescription:"Micron21 Datacentre Pty Ltd",
          • stringcountry:"AU",
        • objectpeers[4]:Object,
          • stringas_number:"AS401181",
          • stringdescription:"Cordial",
          • stringcountry:"US",
        • objectpeers[5]:Object,
          • stringas_number:"AS24953",
          • stringdescription:"NETPLANET GmbH",
          • stringcountry:"AT",
        • objectpeers[6]:Object,
          • stringas_number:"AS25048",
          • stringdescription:"DSNET Ltd",
          • stringcountry:"GB",
        • objectpeers[7]:Object,
          • stringas_number:"AS47697",
          • stringdescription:"BIX.BG Ltd.",
          • stringcountry:"BG",
        • objectpeers[8]:Object,
          • stringas_number:"AS6079",
          • stringdescription:"RCN",
          • stringcountry:"US",
        • objectpeers[9]:Object,
          • stringas_number:"AS22548",
          • stringdescription:"Núcleo de Inf. e Coord. do Ponto BR NIC.BR",
          • stringcountry:"BR",
        • ... and 849 more
      • stringwhois_response:" # # ARIN WHOIS data and services are subject to the Terms of Use # available at: https://www.arin.n...",
  • Active ASNs
    131K+
    Announced IPv4 routes
    1.3M+
    Announced IPv6 prefixes
    298.7K+
    Network organizations
    93.4K+
    Amazon
    Checkout
    ReversingLabs
    AT&T
    Ford
    HPE
    IKEA
    Intelitics
    Verizon
    Mercedes-Benz
    NEC
    Pfizer
    Roche
    SpaceX
    Tencent
    Toyota
    Virtusa
    VMware
    Wix
    Xero
    Amazon
    Checkout
    ReversingLabs
    AT&T
    Ford
    HPE
    IKEA
    Intelitics
    Verizon
    Mercedes-Benz
    NEC
    Pfizer
    Roche
    SpaceX
    Tencent
    Toyota
    Virtusa
    VMware
    Wix
    Xero
    Live Response

    One call, the whole
    network profile

    One request with include=peers,downstreams, upstreams,routes,whois_response returns everything this page describes. The response below is a real, current output for AS12 (New York University).

    Full API Docs
    Request
    curl "https://api.ipgeolocation.io/v3/asn?apiKey=<API_KEY>&asn=12&include=peers,downstreams,upstreams,routes,whois_response"
    Response Preview
    1{
    2  "asn": {
    3    "as_number": "AS12",
    4    "organization": "New York University",
    5    "country": "US",
    6    "type": "EDUCATION",
    7    "domain": "nyu.edu",
    8    "date_allocated": "1984-07-05",
    9    "asn_name": "NYU-DOMAIN",
    10    "allocation_status": "",
    11    "num_of_ipv4_routes": 12,
    12    "num_of_ipv6_routes": 1,
    13    "rir": "ARIN",
    14
    15    "routes": [
    16      "192.76.177.0/24",
    17      "216.165.96.0/20",
    18      "2607:f600::/32",
    19      "... 10 more routes"
    20    ],
    21
    22    "downstreams": [
    23      {
    24        "as_number": "AS394666",
    25        "description": "NYU Langone Health",
    26        "country": "US"
    27      }
    28    ],
    29
    30    "upstreams": [
    31      {
    32        "as_number": "AS3269",
    33        "description": "Telecom Italia S.p.A.",
    34        "country": "IT"
    35      },
    36      {
    37        "as_number": "AS8220",
    38        "description": "COLT Technology Services Group Limited",
    39        "country": "GB"
    40      },
    41      {
    42        "as_number": "AS286",
    43        "description": "GTT Communications Inc.",
    44        "country": "US"
    45      },
    46      "... 5 more upstreams"
    47    ],
    48
    49    "peers": [
    50      {
    51        "as_number": "AS3269",
    52        "description": "Telecom Italia S.p.A.",
    53        "country": "IT"
    54      },
    55      {
    56        "as_number": "AS8220",
    57        "description": "COLT Technology Services Group Limited",
    58        "country": "GB"
    59      },
    60      {
    61        "as_number": "AS394666",
    62        "description": "NYU Langone Health",
    63        "country": "US"
    64      },
    65      "... 8 more peers"
    66    ],
    67
    68    "whois_response": "#
    69# ARIN WHOIS data and services 
    70are subject to the Terms of Use
    71# available at: 
    72
    73https://www.arin.net/resources/registry/whois/tou/
    74..."
    75  }
    76}
    What API Offers

    What You Get in Every ASN Lookup

    Every ASN lookup returns the full identity of a network: who owns it, what type it is, where it is registered, what it announces, and who it connects to.

    Upstream Module

    The upstream providers of a target AS organization are the networks that supply its internet connectivity and routing. Knowing the transit providers of an ASN helps in understanding how traffic enters the network and which providers it relies on for connectivity. Understanding upstream relationships helps in making improved backup strategies if an upstream provider goes down or experiences difficulties.

    Full API Docs
    Response Preview
    1{
    2  "asn": {
    3    "as_number": "AS1",
    4    "organization": "Level 3 Parent, LLC",
    5    "country": "US",
    6    "...":"..."
    7    "upstreams": [
    8      {
    9        "as_number": "AS7046",
    10        "description": "Verizon Business",
    11        "country": "US"
    12      },
    13      {
    14        "as_number": "AS51925",
    15        "description": "NUVEI BULGARIA EOOD",
    16        "country": "BG"
    17      },
    18      "...":"..."
    19    ]
    20  }
    21}

    IP to ASN lookup, and ASN to IP ranges

    Pass ip= and the API resolves any IPv4 or IPv6 address to its origin AS, then returns the same full profile. Pass asn= and it works the other way: the AS number expands into its announced IPv4 and IPv6 ranges. Both directions cost one credit.

    1{
    2  "ip": "8.8.8.8",
    3  "asn": {
    4    "as_number": "AS15169",
    5    "organization": "Google LLC",
    6    "country": "US",
    7    "type": "BUSINESS",
    8    "domain": "google.com",
    9    "date_allocated": "2000-03-30",
    10    "asn_name": "GOOGLE",
    11    "allocation_status": "assigned",
    12    "num_of_ipv4_routes": 1066,
    13    "num_of_ipv6_routes": 157,
    14    "rir": "ARIN",
    15
    16    "routes": [
    17      "108.177.103.0/24",
    18      "192.178.131.0/24",
    19      "34.190.176.0/21",
    20      "... 1220 more routes"
    21    ],
    22
    23    "downstreams": [
    24      {
    25        "as_number": "AS36040",
    26        "description": "Google Fiber Inc.",
    27        "country": "US"
    28      },
    29      {
    30        "as_number": "AS139190",
    31        "description": "Google Asia Pacific",
    32        "country": "SG"
    33      },
    34      {
    35        "as_number": "AS16550",
    36        "description": "Google Ireland Limited",
    37        "country": "IE"
    38      },
    39      "... + 17 more downstreams"
    40    ],
    41
    42    "upstreams": [
    43      {
    44        "as_number": "AS3356",
    45        "description": "Level 3 Parent, LLC",
    46        "country": "US"
    47      },
    48      {
    49        "as_number": "AS1299",
    50        "description": "Arelion",
    51        "country": "SE"
    52      },
    53      {
    54        "as_number": "AS2914",
    55        "description": "NTT Communications",
    56        "country": "JP"
    57      },
    58      "... + 137 more upstreams"
    59    ],
    60
    61    "peers": [
    62      {
    63        "as_number": "AS3356",
    64        "description": "Level 3 Parent, LLC",
    65        "country": "US"
    66      },
    67      {
    68        "as_number": "AS1299",
    69        "description": "Arelion",
    70        "country": "SE"
    71      },
    72      {
    73        "as_number": "AS6939",
    74        "description": "Hurricane Electric",
    75        "country": "US"
    76      },
    77      "... + 715 more peers"
    78    ],
    79
    80    "whois_response": "ASNumber:       15169
    81ASName:         GOOGLE
    82OrgName:        Google LLC
    83..."
    84  }
    85}
    ASN World Map
    Response Data

    What the ASN API returns

    Six groups of data in every full lookup. Each card summarizes one; the docs carry the field-by-field reference for all of them.

    Core ASN record

    The AS number, owning organization, ASN type (ISP, hosting, business, education, or government), website, country of registration, RIR, allocation date, and current allocation status. Enough to answer 'who runs this network' from a single object.

    Route prefixes

    Every IPv4 and IPv6 prefix the AS announces to the global routing table, plus per-family route counts. Use it for allowlists, blocklists, route filtering, and footprint analysis.

    Peers

    The networks this AS exchanges traffic with directly, each with its AS number, name, and country. Peering breadth is the fastest read on how well-connected a network is.

    Downstreams

    The customer networks that receive connectivity through this AS. Downstream chains let security teams trace where a suspicious network actually gets its transit.

    Upstreams

    The transit providers this AS relies on to reach the rest of the internet. Upstream lists reveal dependency: one upstream is a single point of failure, five is resilience.

    WHOIS record

    The raw registry text for the ASN: registrant organization, handles, registration and update dates, and points of contact. No second WHOIS query needed.

    Full field reference in the ASN API Docs

    Data Foundation

    How the
    ASN data stays current

    The ASN dataset is rebuilt every day from two source families: global BGP routing feeds, which show what every AS actually announces and who it connects through, and the five regional internet registries which hold the registration record

    step-1

    Collect

    Routing table snapshots and live update streams from BGP vantage points worldwide, alongside delegation files and WHOIS records from all five RIRs.

    step-2

    Clean

    Deduplicate announcements across vantage points, drop bogon and reserved space, filter route leaks and flap noise, and expire prefixes that leave the routing table.

    step-3

    Extract Routes

    Map every announced IPv4 and IPv6 prefix to its origin AS, producing the per-ASN route lists and counts the API returns.

    step-4

    Map Relationships

    Analyze observed AS paths to classify each adjacency as customer, provider, or peer. That classification is what the API serves as upstreams, downstreams, and peers.

    step-5

    Enrich and Normalize

    Registry records merge into the routing view and organization names are normalized. Each ASN then carries its type and registration details.

    step-6

    Publish

    The rebuilt dataset ships daily to the ASN API and the downloadable databases, and the build date renders in the stat band above.

    cta

    The API itself runs on global edge infrastructure with a 99.99% uptime SLA; current latency is public on the status page

    Request Demo
    Compare

    What most ASN lookups leave out

    ASN data comes in four packages: free lookup tools, lite databases, geolocation APIs with an ASN field, and dedicated ASN APIs. They answer different questions, and most stop well before the relationship data.

    What to checkFree lookup toolsLite ASN databasesGeolocation APIs with an ASN fieldIPGeolocation ASN API
    Lookup directionsIP or ASN, in a browser, rate-cappedIP ranges to ASN onlyIP only
    IP and ASN, by API
    Core recordAS number, name, organization2 to 5 fields per rowAS number and organization
    Organization, type, website, country, RIR, allocation date, status
    Route prefixesRareNot per ASNTypically absent
    IPv4 and IPv6, with counts
    Peers, upstreams, downstreamsNot returnedNot includedNot included
    All three, in one response
    WHOIS recordSeparate toolNot includedNot included
    Raw registry text in the response
    Update cadenceRarely statedMonthly is commonVaries by plan
    Daily, build date shown

    If the question is "who is this network and who moves its traffic," only the last column answers it.

    Related Products

    The Same Data Other Shapes

    Resolving addresses at scale? The IP to ASN Database ships the same mapping as a daily-updated MMDB or CSV for local, zero-latency lookups. For an IP's location, currency, timezone alongside basic ASN data, use the IP Geolocation API.

    IP to ASN Database

    IP to ASN Database

    The full IP-to-ASN mapping as daily-updated MMDB and CSV files for local, zero-latency resolution at any volume.

    View IP to ASN Database
    ASN WHOIS Database

    ASN WHOIS Database

    Registration and ownership records for every allocated ASN, built for compliance research and bulk attribution work.

    View ASN WHOIS Database
    IP Geolocation API

    IP Geolocation API

    Location, currency, timezone, company, and basic ASN data for any IP in one combined response.

    View IP Geolocation API
    Tier Overview

    Explore the Geo Advance Database Tier

    Explore every Geo Advance database in one place, including geolocation, ASN, company, and WHOIS data, then pick individual datasets or build a custom mix. Compare bundles that pair Geo Advance with Geo Standard or Security Pro. Includes sample data, schemas, update cadence, and field lists for every database in the tier.

    View Geo Advance Tier
    Daily & weekly updates
    Sub-millisecond local lookups
    Locally Hosted Data
    MMDB, CSV, and JSON formats
    No per-query costs or rate limits
    Geo Advance database preview

    Use Cases

    Cybersecurity and Threat Detection

    ASN data helps security teams identify the source of malicious network activity with greater precision. By continuously monitoring ASN-related patterns, security professionals can detect anomalies more quickly and mitigate emerging threats before they escalate. Leveraging this intelligence allows them to make smarter, data-driven decisions, and proactively defend their infrastructure.

    cybersecurity

    Network Performance and Routing Optimization

    Network engineers can analyze ASN data to optimize routing paths and reduce latency. An understanding of peering relationships between ASNs helps them identify the optimal path for data packets, ensuring efficient data delivery and an improved user experience. Additionally, by utilizing peering information, ISPs can bypass transit providers and reduce operational costs.

    route-optimization

    Business and Market Analysis

    By understanding where internet connections are coming from (geolocation) and which network they belong to (ASN information), businesses can get a much clearer and more accurate picture of where their customers are, which internet companies or organizations they use, and how people in different areas are using their services. This deeper understanding helps them build more effective marketing strategies, make customer interactions feel more personal, and focus on reaching the right people to get the best results.

    business-analysis

    Fraud Detection and Prevention

    Financial institutions and e-commerce platforms can use ASN finder tools to identify suspicious transactions and activities originating from high-risk ASNs. By pinpointing these potential threats early, organizations can make smarter decisions, such as implementing additional verification steps, monitoring high-risk traffic more closely, and proactively preventing fraudulent activities. This not only strengthens security measures but also builds greater trust with customers by safeguarding their financial and personal information.

    fraud-prevention

    Network Infrastructure Planning

    By observing ASN peering relationships, upstream providers, and downstream organizations, ISPs can strategically plan which ASes they should connect to in order to make optimal decisions for their network infrastructure. Through careful analysis of traffic patterns, capacity demands, and geographic distribution, ISPs can design a more efficient, resilient, and cost-effective network. This proactive approach improves overall network performance, reduces latency, and minimizes dependency on costly transit providers, ensuring better service quality for end users.

    network-infra

    ASN Lookup API FAQs

    Basic ASN data is free. Every free-plan IP Geolocation API response includes the AS number , organization, and country for an IP, with 1,000 credits per day . The dedicated ASN API , which adds routes, peers, upstreams, downstreams, and WHOIS data, is available on paid plans starting from $19/month , and a free trial can be activated through support.

    Yes. Pass ip= with any IPv4 or IPv6 address and the API resolves it to the origin AS before returning the complete ASN profile, including routes and relationships when requested. Passing asn= queries a network directly. If both are provided, asn= takes priority. If neither is supplied, the API resolves the caller's IP address.

    The ASN dataset is updated daily . It is rebuilt every day using BGP routing feeds and data from the five Regional Internet Registries (RIRs), ensuring new allocations, route changes, and relationship updates are reflected in the next build. The same update schedule also applies to the IP to ASN Database.

    Yes. The ASN API fully supports IPv6. IP-to-ASN lookups accept IPv6 addresses, and every ASN profile includes announced IPv6 prefixes and IPv6 route counts alongside IPv4 information. IPv6 lookups do not incur additional charges and are available on the same plans as IPv4.

    Every lookup returns the core ASN record, including the AS number , owning organization, type, website, registration country, RIR, allocation date, status, and route counts. Using the include parameter adds announced IPv4 and IPv6 prefixes, peers, upstreams, downstreams, and the raw WHOIS record. The ASN API documentation lists every response field with its type and empty-state behavior.

    They describe the three relationship types around an autonomous system. Peers exchange traffic directly, typically settlement-free. Upstreams are transit providers the network relies on to reach the wider internet. Downstreams are customer networks that depend on it for internet connectivity. Together they provide a complete picture of a network's connectivity and dependencies.

    Every successful ASN lookup costs 1 credit , regardless of how many include options are requested. Paid plans start at $19/month with 150,000 credits , and there are no rate limits. Every response includes the X-Credits-Charged header for transparent billing. See the Credits Usage Guide for complete details.

    Yes. The IP to ASN Database provides daily updated IP-range-to-ASN mappings with organization, network type, route counts, and peer counts in MMDB and CSV formats. The ASN WHOIS Database contains ASN registration and ownership records, making both databases ideal for batch enrichment, air-gapped deployments, and low-latency local lookups.

    Ready to get started? Add ASN Lookup API to your stack today

    Enrich every request with precise geolocation and real-time threat intelligence, delivered on a global edge with a 99.99% uptime SLA. Start free and scale when you’re ready.

    CTA Illustration
    CTA Illustration

    Subscribe to Our Newsletter

    Get the latest in geolocation tech, straight to your inbox.